CVE-2025-21482
7.1Qualcomm · Snapdragon
A cryptographic vulnerability exists in various Qualcomm Snapdragon modems and processors during RSA PKCS padding decoding, potentially allowing unauthorized data access or integrity compromise.
Executive summary
A cryptographic flaw in Qualcomm Snapdragon hardware components may allow local attackers with low privileges to compromise data confidentiality and integrity.
Vulnerability
This issue involves improper RSA PKCS padding decoding, classified under CWE-310. The vulnerability requires local access and low privileges to exploit, as indicated by the CVSS vector (AV:L/PR:L).
Business impact
The vulnerability carries a CVSS score of 7.1, reflecting a high severity due to its potential for significant data compromise. Successful exploitation could lead to unauthorized access to sensitive information or the manipulation of data processed by the affected modems and processors, posing a substantial risk to system integrity and operational security.
Remediation
Immediate Action: Review the official Qualcomm security bulletin for September 2025 to identify specific firmware or driver updates for your hardware configuration and apply them immediately.
Proactive Monitoring: Monitor system logs for unusual cryptographic errors or unexpected service behavior that may indicate an attempt to exploit padding vulnerabilities.
Compensating Controls: Ensure that systems using these components are physically secured and that access to the local environment is restricted to authorized personnel only, as the vulnerability requires local access.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
Given the potential for high impact on data confidentiality and integrity, organizations utilizing the affected Qualcomm Snapdragon hardware must prioritize the application of vendor-supplied firmware updates. Users should consult the Qualcomm security portal to verify if a patch is available for their specific device model and implement it as part of standard hardware maintenance cycles.